mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-07 11:06:19 +00:00
926 B
926 B
CVE-2020-8893
Description
An issue was discovered in MISP before 2.4.121. The Galaxy view contained an incorrectly sanitized search string in app/View/Galaxies/view.ctp.
POC
Reference
- https://zigrin.com/advisories/misp-bruteforce-protection-not-working-in-very-specific-environments/
- https://zigrin.com/advisories/misp-bruteforce-protection-not-working-in-very-specific-environments/
- https://zigrin.com/advisories/misp-reflected-xss-in-galaxy-view/
- https://zigrin.com/advisories/misp-reflected-xss-in-galaxy-view/